The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function.
References
Configurations
History
No history.
Information
Published : 2009-07-07 23:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-2355
Mitre link : CVE-2009-2355
CVE.ORG link : CVE-2009-2355
JSON object : View
Products Affected
dan_cahill
- nulllogic_groupware
CWE
CWE-189
Numeric Errors